2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-9486 | — | — | 1.2% | Jul 13, 2018 | On Windows endpoints, the SecureConnector agent must run under the local SYSTEM account or another administrator account... |
| CVE-2016-9485 | — | — | 1.2% | Jul 13, 2018 | On Windows endpoints, the SecureConnector agent must run under the local SYSTEM account or another administrator account... |
| CVE-2016-9484 | — | — | 4.4% | Jul 13, 2018 | The generated PHP form code does not properly validate user input folder directories, allowing a remote unauthenticated ... |
| CVE-2016-9483 | — | — | 3.5% | Jul 13, 2018 | The PHP form code generated by PHP FormMail Generator deserializes untrusted input as part of the phpfmg_filman_download... |
| CVE-2016-9482 | — | — | 4.7% | Jul 13, 2018 | Code generated by PHP FormMail Generator may allow a remote unauthenticated user to bypass authentication in the to acce... |
| CVE-2016-6578 | HIGH | 8.8 | 0.9% | Jul 13, 2018 | CodeLathe FileCloud, version 13.0.0.32841 and earlier, contains a global cross-site request forgery (CSRF) vulnerability... |
| CVE-2016-6567 | — | — | 2.9% | Jul 13, 2018 | SHDesigns' Resident Download Manager provides firmware update capabilities for Rabbit 2000/3000 CPU boards, which accord... |
| CVE-2016-6566 | — | — | 11.8% | Jul 13, 2018 | The valueAsString parameter inside the JSON payload contained by the ucLogin_txtLoginId_ClientStat POST parameter of the... |
| CVE-2016-6565 | — | — | 2.5% | Jul 13, 2018 | The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 does not properly validate user input in the cs... |
| CVE-2016-6564 | — | — | 2.7% | Jul 13, 2018 | Android devices with code from Ragentek contain a privileged binary that performs over-the-air (OTA) update checks. Addi... |
| CVE-2016-6563 | — | — | 79.9% | Jul 13, 2018 | Processing malformed SOAP messages when performing the HNAP Login action causes a buffer overflow in the stack in some D... |
| CVE-2016-6562 | — | — | 0.4% | Jul 13, 2018 | On iOS and Android devices, the ShoreTel Mobility Client app version 9.1.3.109 fails to properly validate SSL certificat... |
| CVE-2016-6559 | — | — | 3.7% | Jul 13, 2018 | Improper bounds checking of the obuf variable in the link_ntoa() function in linkaddr.c of the BSD libc library may allo... |
| CVE-2016-6558 | — | — | 3.5% | Jul 13, 2018 | A command injection vulnerability exists in apply.cgi on the ASUS RP-AC52 access point, firmware version 1.0.1.1s and po... |
| CVE-2016-6557 | — | — | 0.9% | Jul 13, 2018 | In ASUS RP-AC52 access points with firmware version 1.0.1.1s and possibly earlier, the web interface, the web interface ... |
| CVE-2016-6554 | — | — | 4.1% | Jul 13, 2018 | Synology NAS servers DS107, firmware version 3.1-1639 and prior, and DS116, DS213, firmware versions prior to 5.2-5644-1... |
| CVE-2016-6553 | — | — | 2.9% | Jul 13, 2018 | Nuuo NT-4040 Titan, firmware NT-4040_01.07.0000.0015_1120, uses non-random default credentials of: admin:admin and local... |
| CVE-2016-6552 | — | — | 2.9% | Jul 13, 2018 | Green Packet DX-350 uses non-random default credentials of: root:wimax. A remote network attacker can gain privileged ac... |
| CVE-2016-6551 | — | — | 2.9% | Jul 13, 2018 | Intellian Satellite TV antennas t-Series and v-Series, firmware version 1.07, uses non-random default credentials of: ft... |
| CVE-2016-6549 | — | — | 1.1% | Jul 13, 2018 | The Zizai Tech Nut device allows unauthenticated Bluetooth pairing, which enables unauthenticated connected applications... |
| CVE-2016-6548 | — | — | 3.7% | Jul 13, 2018 | The Zizai Tech Nut mobile app makes requests via HTTP instead of HTTPS. These requests contain the user's authenticated ... |
| CVE-2016-6547 | — | — | 0.4% | Jul 13, 2018 | The Zizai Tech Nut mobile app stores the account password used to authenticate to the cloud API in cleartext in the cach... |
| CVE-2016-6546 | — | — | 0.4% | Jul 13, 2018 | The iTrack Easy mobile application stores the account password used to authenticate to the cloud API in base64-encoding ... |
| CVE-2016-6545 | — | — | 3.1% | Jul 13, 2018 | Session cookies are not used for maintaining valid sessions in iTrack Easy. The user's password is passed as a POST para... |
| CVE-2016-6544 | — | — | 3.4% | Jul 13, 2018 | getgps data in iTrack Easy can be modified without authentication by setting the data using the parametercmd:setothergps... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now